Join our Newsletter — 33% off our NHI Course

What breaks when password reset and device enrolment are not tightly controlled?

An attacker can convert a single successful social engineering call into a valid session, then extend that access through new device enrolment or federation artefacts. That breaks the assumption that MFA remains a hard gate, because the gate has already been moved into a less protected operational process.